Auditable by design.
Governance isn’t a checkbox we bolt on — it’s wired into every answer, every record, and every charge, so you can prove what the AI did.
Guardrails on every answer
PII redaction, jailbreak detection, topic control, and grounding checks run on every reply — always on, never optional.
Hash-chained audit log
Every action is recorded in a tamper-evident chain and independently verifiable.
/v1/audit/verifyDispute any charge
Every verified resolution is inspectable and reversible — dispute any charge in one click.
Security practices
Encryption in transit & at rest
Traffic is encrypted with TLS, and data is encrypted at rest. Secrets are encrypted and access-controlled.
Tenant isolation
Every workspace’s data is isolated at the database layer with row-level security and forced tenant scoping.
Scoped API keys & signed webhooks
Grant least-privilege access with scoped keys; verify every webhook with a signed, timestamped signature.
PII redaction & guardrails
PII is redacted and jailbreak/grounding checks run on every reply — always on, never optional.
EU data residency
Eligible customers can keep data in the EU. No customer content is used to train foundation models.
Hash-chained audit log
Every action is recorded in a tamper-evident chain you can verify independently via /v1/audit/verify.
SOC 2 is in progress. We’re happy to share our current posture and roadmap with design partners under NDA.
Security your team can actually verify.
Talk to us about compliance, residency, and the audit trail.
Supervised alpha · No credit card · You’ll never be billed for a handoff.